threat-intel AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking Atalanta has developed ‘Argo,’ an AI-assisted tool designed to proactively identify vulnerabilities in software and internet-connected systems, specifically to bolster defenses against ongoing cyber threats from Russia a… SecurityWeek · Aug 20, 2026 High RUIRaivulnerabilitycybersecurity
vulnerability NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands A security vulnerability in NASA/JPL's AMMOS Instrument Toolkit's AIT-GUI browser-based operator console allows unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. Researchers at Cycode d… The Hacker News · Aug 20, 2026 High CVE-2026-60112CVE-2026-47731CVE-2026-71214browserauthenticationcommand-injection
threat-intel ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud ToxicPanda 2.0, an Android banking trojan, has significantly expanded its capabilities and targeting scope, now leveraging a new set of remote commands and a sophisticated overlay-based credential theft mechanism. Simult… The Hacker News · Aug 20, 2026 High SOUNbanking trojanandroid malwarecredential theft
threat-intel OpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses OpenAI is significantly bolstering its AI model security with a new, multi-layered monitoring system and operational pauses. Following incidents involving similar AI models and a security breach at Hugging Face, the comp… SecurityWeek · Aug 20, 2026 High aicybersecuritymonitoring
threat-intel UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities Chinese-speaking intrusion actor UAT-10147 is employing a sophisticated, cross-platform intrusion toolset, SPECTRE, leveraging AI-assisted development to evade detection. SPECTRE is a cross-platform backdoor with Linux r… Cisco Talos · Aug 20, 2026 High CVE-2019-16098CVE-2021-21551CHaiedrlinux
threat-intel UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations Chinese-speaking cybercrime group UAT-10147 is leveraging AI-powered tools to automate complex post-compromise operations targeting web servers globally. The group, active since early 2026, utilizes a combination of publ… Cisco Talos · Aug 20, 2026 High CVE-2022-0995CVE-2021-3156CVE-2015-5287CHBRBOaiautomationpost-exploitation
threat-intel Identity Abuse Through Trusted Communication Channels Threat actors are increasingly leveraging trusted collaboration platforms – like Microsoft Teams and Slack – to conduct sophisticated identity phishing attacks. Instead of relying solely on traditional email phishing, at… Palo Alto Unit 42 · Aug 20, 2026 High PONOidentity phishingcollaboration platformssocial engineering
threat-intel Police Are Hiding Their Use of Flock Surveillance Cameras Iowa police are actively concealing their use of Flock license plate reader cameras, a system that tracks vehicle movements. This secrecy stems from a specific usage policy instructing officers not to disclose the camera… Schneier on Security · Aug 20, 2026 Medium surveillanceprivacylicense-plates
threat-intel 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets A group of 40 malicious Firefox extensions, disguised as Web3 products like OKX and Rabby Wallet, are stealing user wallet secrets. These extensions, part of a larger campaign dubbed ‘Offside Wallet Theft Factory,’ have… The Hacker News · Aug 20, 2026 High firefoxwalletextension
vulnerability Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler Citrix has announced patches for a critical authentication bypass vulnerability in its NetScaler ADC and NetScaler Gateway products. This flaw, with a CVSS score of 9.3, allows unauthenticated remote attackers to gain ac… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19490CVE-2026-19489patchauthenticationvulnerability
vulnerability Critical GitLab Flaw Exploited Shortly After Disclosure A critical vulnerability in GitLab (CVE-2026-19478) was quickly exploited by threat actors shortly after its disclosure. The code injection flaw allowed unauthenticated users to delete public projects and modify user dat… SecurityWeek · Aug 20, 2026 Critical CVE-2026-19478gitlabvulnerabilitygraphql
threat-intel Hackers Using AI to Target Siemens PLCs in Critical US Sectors US government agencies have issued a cybersecurity advisory warning critical infrastructure organizations about a growing threat of hackers using AI to target Siemens PLCs. The attackers are scanning for exposed PLCs and… SecurityWeek · Aug 20, 2026 High USicsplccybersecurity
threat-intel AI agent suggested installing a malware package. Engineer almost took its advice A security researcher was nearly tricked into installing malware by an AI agent. The AI, mimicking a support tool, suggested installing a package that would have installed malicious software, highlighting a growing risk… The Register · Aug 20, 2026 Medium aisocial engineeringphishing
vulnerability Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload PHP files and execute code, potentially leading to remote code execution. The flaw stems from a d… The Hacker News · Aug 20, 2026 High CVE-2026-32475CVE-2026-65640wordpressvulnerabilityremote-code-execution
threat-intel Pakistan's Transparent Tribe Refreshes Toolset for Afghan Cyberattacks Pakistan's Transparent Tribe, a known advanced persistent threat (APT) group, has been aggressively targeting organizations in Afghanistan and India, utilizing a refined toolset including the Patchcord backdoor and other… Dark Reading · Aug 20, 2026 High AFINPAaptsocial engineeringbrowser hijacking
threat-intel ISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques to steal credentials. The threat landscape is evolving rapi… SANS Internet Storm Center · Aug 20, 2026 High phishingcredential theftlateral movement
vulnerability Multiples vulnérabilités dans les produits Cisco (20 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including BroadWorks Application Delivery Platform, BroadWorks Application Server, and BroadWorks Profile Server. These vulnerabilities allow for remote co… CERT-FR · Aug 20, 2026 High CVE-2026-20030CVE-2026-20231CVE-2026-20315ciscovulnerabilityremote code execution
vulnerability Multiples vulnérabilités dans Ceph (20 août 2026) Multiple vulnerabilities have been discovered in Ceph, allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect older versions of the distrib… CERT-FR · Aug 20, 2026 High CVE-2025-30156CVE-2026-39944CVE-2026-50152cephvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Citrix (20 août 2026) Multiple vulnerabilities have been discovered in Citrix products, including NetScaler ADC and NetScaler Gateway. These flaws could allow attackers to cause a denial-of-service, bypass security policies, and create an uns… CERT-FR · Aug 20, 2026 Medium CVE-2026-19489CVE-2026-19490citrixvulnerabilitysecurity
vulnerability Multiples vulnérabilités dans les produits Splunk (20 août 2026) Multiple vulnerabilities have been discovered in Splunk products, including remote code execution, privilege escalation, and data confidentiality breaches. Several of these vulnerabilities can be exploited to achieve rem… CERT-FR · Aug 20, 2026 CVE-2024-35255CVE-2025-13465CVE-2025-13473vulnerabilitydata breachsupply chain